Cyber Security News

Hunters International Overlaps Hive Ransomware Attacking Windows, Linux, and ESXi Systems

A sophisticated ransomware operation known as Hunters International emerged in October 2023, with strong evidence suggesting connections to the formerly dismantled Hive ransomware group.

The initial attack was documented on October 13, 2023, when the group disclosed their first victim—an English company—on their data leak site.

Hunters International’s data leak site (Source – Group-IB)

Security researchers quickly identified similarities between the new ransomware and Hive’s code structure, suggesting that former Hive operators may have rebranded following law enforcement disruption earlier that year.

Hunters International demonstrates remarkable cross-platform capabilities, targeting Windows, Linux, FreeBSD, SunOS, and ESXi systems across x64, x86, and ARM architectures.

This versatility enables the threat actors to compromise diverse enterprise environments, with particular focus on real estate, healthcare, and professional services industries.

The attackers leverage a multi-stage approach, first exfiltrating sensitive data before deploying encryption payloads, establishing a powerful double extortion mechanism.

Group-IB researchers discovered that the operation provides affiliates with sophisticated tools, including the ransomware itself and a “Storage Software” utility designed to organize exfiltrated data.

Hunters International’s affiliate panel (Source – Group-IB)

Their analysis revealed striking technical overlaps with Hive’s ransomware, particularly in encryption methods and command-line functionalities.

The operation has evolved significantly over time, with version 6 (released August 2024) implementing a “quiet mode” that no longer renames encrypted files or drops ransom notes—a technique similarly adopted by LockBit 4.

This evolution reflects the operators’ recognition that traditional indicators of compromise reduce payment likelihood when detected by security teams or regulators.

Detection Evasion Techniques

Hunters International employs multiple evasion tactics to remain undetected during execution.

For Windows systems, the ransomware is distributed as both executable and DLL formats, with the latter enabling execution through legitimate Windows processes.

Here the attackers can deploy the malware using trusted binaries:-

regsvr32.exe /c /n /i:"[OPTIONS] [PATHS]..." encrypter_windows_x64.dll

The ransomware preserves the first 0x41 bytes of each file, checking bytes 0x45-0x58 against a hardcoded value (‘A88830F163306FFE4E4C50EE730476D30C3CE4’) to determine if files have already been encrypted.

This selective encryption approach preserves file signatures, further complicating detection efforts. For ESXi environments, the operators provide specific instructions to disable security controls:-

esxcli system settings advanced set -o /VMkernel/execInstalledOnly -i 0

Ransomware groups rely on skilled operators to adapt tactics. Group-IB reveals Hunters International’s evolving strategies based on global events.

Due to law enforcement crackdowns, attackers now target critical infrastructure, believing essential services will pay higher ransoms.

Ransomware payments are dropping while extortion-only payments rise which shoes, that groups may shift to exfiltration-only attacks with automation.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

5 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

6 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

7 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

7 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

7 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

7 hours ago